SourceCodester Yoga Class Registration System Status Update update_status.php sql injection
CVE-2023-0980

9.8CRITICAL

Key Information:

Vendor
CVE Published:
23 February 2023

Summary

A vulnerability has been identified in SourceCodester's Yoga Class Registration System, specifically within the Status Update Handler component found in the admin/registrations/update_status.php file. This vulnerability arises from improper handling of the 'id' argument, allowing for potential SQL injection attacks. Attackers may exploit this vulnerability remotely, manipulating SQL queries to gain unauthorized access to sensitive data or execute malicious commands.

Affected Version(s)

Yoga Class Registration System 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mroz1l (VulDB User)
.